CVE-2022-27850: WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-27850?
CVE-2022-27850 is a vulnerability called Cross-Site Request Forgery (CSRF) in Simple Ajax Chat WordPress plugin, allowing an attacker to clear the chat log or delete a chat message.
What is the severity of CVE-2022-27850?
The severity of CVE-2022-27850 is medium with a CVSS score of 4.3.
Which software versions are affected by CVE-2022-27850?
The Simple Ajax Chat WordPress plugin versions up to and including 20220115 are affected by CVE-2022-27850.
How can an attacker exploit CVE-2022-27850?
An attacker can exploit CVE-2022-27850 by performing Cross-Site Request Forgery attacks to clear the chat log or delete a chat message.
Is there a fix for CVE-2022-27850?
Yes, a patch is available to fix the vulnerability. Please refer to the provided references for more information.